Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

9/10/2009
04:26 PM
Gadi Evron
Gadi Evron
Commentary
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Blacklisting For Extra Mail Server Security

A majority of systems around the world use Internet blacklists as lists of IP addresses that are most likely compromised -- by bots -- and used by these systems to block or otherwise filter email. However, these lists can sometimes be used beyond the blacklist's design intent for increased security, but only after careful consideration.

A majority of systems around the world use Internet blacklists as lists of IP addresses that are most likely compromised -- by bots -- and used by these systems to block or otherwise filter email. However, these lists can sometimes be used beyond the blacklist's design intent for increased security, but only after careful consideration.By filtering with a blacklist, millions of email servers worldwide manage to stay operational. At the same time, email remains a viable communication medium in spite of the load spam emails put on the infrastructure.

There's never a good time to discover you can't use email, especially while flying around the world on business. This recently happened to me: I was unable to send email, and the error message baffled me. It claimed my IP address was listed in a certain blacklist.

Blacklisting is supposed to be enabled only for other servers trying to connect to mine, so why was the server blocking me, a user, when I authenticated and tried to email?

Turns out the problem was due to a configuration error. But I liked it -- the bug became a feature. One that can be dangerous, though. Find out the acceptable use policy of the blacklist provider for non-standard use like this, and comply with all requirements. For example, the CBL's terms of use are here: http://cbl.abuseat.org/tandc.html.

Because I'm among very few users using this server, the inconvenience was negligible. If I am willing to not email while connecting via insecure networks, then I gain an extra layer of security.

Millions of bot-infected computers are far less likely to be successful in compromising the server because they can't access much of its functionality. Given that most Internet attacks are performed via bots, I feel this raises the security level of the server at the price of being inconvenienced when on the road.

I cannot IP filter an SMTP server to be available only from certain locations -- as if I even wanted to limit myself in such a way. By its very nature as a public service, it needs to be available to the world if I am to receive email from others. And this extra security helps increase my assurance level.

This solution won't work for everybody. Perhaps you are not willing to inconvenience yourself, or perhaps you use a busier server and can't decide on such a measure for the other users. Indeed, for a busy server such as a service provider's, it will simply cause too much problems. But it works for me.

Of course, there are many varied solutions for secure email, from authentication and encryption to using VPN. This only complements them for me under my specific condition of being almost the sole user of this server.

Naturally, this cannot, nor should it, be implemented on email servers with more than just a few users, and existing solutions are more than enough for most. Be careful not to implement it lightly, as it can cause many misconfigurations down the road.

For a view on this from the perspective of a DNSBL operator, see http://cbl.abuseat.org/wrong.html. For further reading on email security, I'd like to direct you to MAAWG's Managing Port25 document.

Follow Gadi Evron on Twitter: http://twitter.com/gadievron

Gadi Evron is an independent security strategist based in Israel. Special to Dark Reading. Gadi is CEO and founder of Cymmetria, a cyber deception startup and chairman of the Israeli CERT. Previously, he was vice president of cybersecurity strategy for Kaspersky Lab and led PwC's Cyber Security Center of Excellence, located in Israel. He is widely recognized for ... View Full Bio

 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/10/2020
Researcher Finds New Office Macro Attacks for MacOS
Curtis Franklin Jr., Senior Editor at Dark Reading,  8/7/2020
Exploiting Google Cloud Platform With Ease
Dark Reading Staff 8/6/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-8904
PUBLISHED: 2020-08-12
An arbitrary memory overwrite vulnerability in the trusted memory of Asylo exists in versions prior to 0.6.0. As the ecall_restore function fails to validate the range of the output_len pointer, an attacker can manipulate the tmp_output_len value and write to an arbitrary location in the trusted (en...
CVE-2020-8905
PUBLISHED: 2020-08-12
A buffer length validation vulnerability in Asylo versions prior to 0.6.0 allows an attacker to read data they should not have access to. The 'enc_untrusted_recvfrom' function generates a return value which is deserialized by 'MessageReader', and copied into three different 'extents'. The length of ...
CVE-2020-12106
PUBLISHED: 2020-08-12
The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows unauthenticated users to send HTTP POST request to several critical Administrative functions such as, changing credentials of the Administrator account or connect the product to a rogue access point.
CVE-2020-12107
PUBLISHED: 2020-08-12
The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows command injection via a text field, which allow full control over this module's Operating System.
CVE-2020-7374
PUBLISHED: 2020-08-12
Documalis Free PDF Editor version 5.7.2.26 and Documalis Free PDF Scanner version 5.7.2.122 do not appropriately validate the contents of JPEG images contained within a PDF. Attackers can exploit this vulnerability to trigger a buffer overflow on the stack and gain remote code execution as the user ...